By now, you’ve no doubt heard of WannaCry, the ransomware attack that impacted over 300,000 victims in more than 100 countries over the past 10 days. While we’ve all focused on effective patching strategies to prevent further infection, an important part of the discussion is how to plan for a successful incident response (IR) to ransomware and other types of attacks.

Nipping Ransomware in the Bud

When dealing with ransomware attacks, the primary goal is to avoid falling victim in the first place. The key is to consistently back up your most critical data. You should also ensure that your backup servers and systems aren’t always connected to the network. That way, a ransomware attack within your environment will have little impact, since you’ll still be able to access your critical data.

That said, an effective backup strategy is simply one part of a larger security and response plan, which should be developed proactively. To successfully combat ransomware and other types of targeted attacks, it’s critical to create an incident response plan, document it and test it regularly to identify gaps and changes within the environment.

Watch the webinar series: Orchestrate Your Security Defenses to Avoid Ransomware Attacks

Building an Effective Incident Response Plan

Organizations that have a documented incident response plan and an IR team, whether it’s internal, external or a combination of both, can respond to a breach more quickly than those who don’t. Organizations that are able to complete an investigation in 30 days or less save an average of $1,000,000 over those who don’t.

Furthermore, organizations that document their plans and test them quarterly or biannually are able to more effectively prepare for security incidents and practice their response actions in advance of a real attack. This allows these enterprises to accelerate the process of response and investigation, greatly reducing data exposure and financial losses.

An effective response plan should contain a broad scope of technical and nontechnical actions that need to be conducted by all stakeholders within the environment. This requires leaders to ask questions such as:

  • Does the information security team have the data needed to perform live responses on hosts in the environment? Is that data searchable from a central location? Are analysts able to pull data from or images of remote hosts when needed?
  • Does the organization have contracts in place with external crisis communications firms, outside legal counsel specializing in privacy and experienced incident response firms who can supplement the internal teams?
  • How do stakeholders within the organization communicate with each other when there is concern that email systems may be compromised by an unauthorized actor?
  • What information are employees authorized to communicate to third parties during a breach, if any? Are employees aware of this policy?
  • What type of communications will be shared with the news media by the organization? Are there holding statements already crafted that can be used in a crisis?

Documenting and regularly testing a variety of scenarios helps organizations determine where gaps may exist. Most importantly, this enables security teams to fix vulnerabilities in advance of a breach.

How IBM Can Help

The X-Force Incident Response and Intelligence Services (IRIS) team specializes in providing incident response planning, program development, response to critical breaches, remediation and threat intelligence to clients in over 133 countries. We have experience responding to and containing many of the largest data breaches in the world.

To learn more:

More from Incident Response

Poor Communication During a Data Breach Can Cost You — Here’s How to Avoid It

5 min read - No one needs to tell you that data breaches are costly. That data has been quantified and the numbers are staggering. In fact, the IBM Security Cost of a Data Breach estimates that the average cost of a data breach in 2022 was $4.35 million, with 83% of organizations experiencing one or more security incidents. But what’s talked about less often (and we think should be talked about more) is how communication — both good and bad — factors into…

5 min read

Ransomware Renaissance 2023: The Definitive Guide to Stay Safer

2 min read - Ransomware is experiencing a renaissance in 2023, with some cybersecurity firms reporting over 400 attacks in the month of March alone. And it shouldn’t be a surprise: the 2023 X-Force Threat Intelligence Index found backdoor deployments — malware providing remote access — as the top attacker action in 2022, and aptly predicted 2022’s backdoor failures would become 2023’s ransomware crisis. Compounding the problem is the industrialization of the cybercrime ecosystem, enabling adversaries to complete more attacks, faster. Over the last…

2 min read

Expert Insights on the X-Force Threat Intelligence Index

5 min read - Top insights are in from this year’s IBM Security X-Force Threat Intelligence Index, but what do they mean? Three IBM Security X-Force experts share their thoughts on the implications of the most pressing cybersecurity threats, and offer guidance for what organizations can do to better protect themselves. Moving Left of Boom: Early Backdoor Detection Andy Piazza, Global Head of Threat Intelligence at IBM Security X-Force, sat down with Security Intelligence to chat with us about the rise in the deployment…

5 min read

How Morris Worm Command and Control Changed Cybersecurity

4 min read - A successful cyberattack requires more than just gaining entry into a victim’s network. To truly reap the rewards, attackers must maintain a persistent presence within the system. After establishing communication with other compromised network devices, actors can stealthily extract valuable data. The key to all this is a well-developed Command and Control (C2 or C&C) infrastructure. The number of C2 servers used for launching cyberattacks increased by 30% in 2022. More than 17,000 of these servers were detected last year,…

4 min read